Privacy policy

PRIVACY POLICY

Last updated: 1 March 2026

Frøken Lilly (“we”, “us”, “our”) is the data controller for the processing of personal data collected via this website and related services (the “Services”), which are provided through Shopify.

This Privacy Policy explains how we collect, process, store, and disclose personal data when you visit the website, make a purchase, or communicate with us.

If there is any conflict between our Terms of Service and this Privacy Policy, this Privacy Policy shall prevail with respect to the processing of personal data.


1. Personal Data We Collect

“Personal Data” means any information that directly or indirectly identifies you or can reasonably be linked to you.

We may collect the following categories of Personal Data:

Contact Information:
Name
Address
Shipping and billing address
Phone number
Email address

Financial Information:
Payment card details (processed exclusively by payment providers)

Transaction and Order Information:
Payment confirmations
Payment method
Shopping cart and wishlist
Purchased, returned, and exchanged products
Order history

Account Information:
Username
Password (encrypted)
Preferences and settings

Communications:
Customer service inquiries
Emails and messages sent to us

Device and Usage Information:
IP address
Browser and device data
Network information
Clicks, views, and traffic history


2. How We Collect Information

We collect information directly from you when you place an order, create an account, contact us, or otherwise use our Services.

We also collect information automatically through cookies and Shopify technologies.

In addition, we may receive information from service providers and partners, including payment providers, shipping partners, marketing platforms, and Shopify.


3. Purposes and Legal Basis for Processing

A) Performance of Contract  
We process Personal Data to handle orders, process payments, deliver products, manage returns, and handle complaints.  
Legal basis: GDPR Article 6(1)(b) (performance of a contract).

B) Customer Service  
We process Personal Data to respond to inquiries and provide support.  
Legal basis: GDPR Article 6(1)(b) and 6(1)(f) (legitimate interest).

C) Marketing and Profiling  
We use cookies and similar technologies to display relevant advertisements, perform segmentation, analyze and optimize marketing activities, and measure campaign performance.

This may include processing IP addresses, device information, behavioral data, purchase history, and email addresses (for newsletters and custom audiences).

We use, among others:
Google (Google Ads and Analytics)
Meta Platforms (Facebook and Instagram)
TikTok
Pinterest
Email marketing platforms

Legal basis: GDPR Article 6(1)(a) (consent).

You may withdraw your consent at any time via cookie settings or the unsubscribe link in marketing emails.

D) Security and Fraud Prevention  
We process Personal Data to prevent misuse and protect our webshop.  
Legal basis: GDPR Article 6(1)(f) (legitimate interest).

E) Accounting and Bookkeeping  
We process Personal Data to comply with accounting and tax legislation.  
Legal basis: GDPR Article 6(1)(c) (legal obligation).


4. Disclosure of Personal Data

We may disclose Personal Data to:

Shopify (hosting and technical operations)
Payment providers
Shipping companies
Accounting systems and auditors
IT and email service providers
Marketing platforms

Shipping companies and payment providers act as independent data controllers.

Other suppliers may act as data processors with whom we have entered into data processing agreements.


5. Relationship with Shopify

Our webshop is hosted by Shopify, which may process Personal Data as part of providing and operating the platform.

Shopify may act as an independent data controller for certain processing activities, including the use of global infrastructure and enhanced platform features.

Shopify’s Privacy Policy is available at:
https://privacy.shopify.com/da


6. International Transfers

Personal Data may be transferred to countries outside the EU/EEA, including the United States.

Transfers take place based on:

European Commission Standard Contractual Clauses (SCCs), and/or  
The EU-U.S. Data Privacy Framework, where applicable.


7. Retention and Deletion

We retain Personal Data only for as long as necessary for the relevant purpose.

Accounting records are retained for 5 years in accordance with Danish bookkeeping law.
Purchase data is retained for up to 5 years.
Complaint cases are retained for up to 3 years from the date of purchase.
Newsletter data is retained until consent is withdrawn. If no activity (such as opens or clicks) has occurred for a continuous period of up to 24 months, the data will be automatically deleted.
Customer inquiries are generally deleted no later than 12 months after completion.
User accounts are deleted after 24 months of inactivity.
Server logs are retained for 6–12 months.

Personal Data may be retained longer if necessary to establish, exercise, or defend legal claims.


8. Your Rights

Under applicable data protection law, you have the right to:

Access your Personal Data
Rectify inaccurate data
Request erasure
Restrict processing
Object to processing
Data portability
Withdraw consent at any time

To exercise your rights, please contact us.

You may lodge a complaint with the Danish Data Protection Agency:
www.datatilsynet.dk


9. Children

The Services are not directed at individuals under the age of 18.


10. Changes

We may update this Privacy Policy from time to time. The date at the top indicates the latest revision.


11. Contact Information

Frøken Lilly
Email: contact@frokenlilly.dk
Address: Fyrrevænget 16, 3630 Jægerspris, Denmark
CVR: 45782158